Home/AI News

AI News

What's Happening in AI, Right Now

Model releases, policy shifts, research breakthroughs, and industry moves, curated and contextualised for professionals who need signal, not noise.

Intelligence, At Your Command.

Latest AI news and analysis

Agents That Can Pay: Gate the Wallet First
AI NewsAnalysis·

Agents That Can Pay: Gate the Wallet First

The rails for agents that pay are being laid in public. Google's Agent Payments Protocol, built with more than sixty payment and technology firms, turns an agent's spending authority into a signed, limited, auditable instruction. Before any tool with a wallet reaches an Australian workplace, the practical question is the action gate: which payments an agent may start, at what limit, with whose approval, and what gets logged.

Read article
Palermo Cala Marina Dusk
AI NewsCapability·

Stop Detecting AI. Start Checking Provenance.

Asking whether a file was made by AI is the wrong question, because the answer is a guess. Provenance asks a different one: what does the file itself carry about where it came from, signed by someone who can be identified. The C2PA specification reached version 2.4 in April 2026, added a machine-readable AI disclosure assertion, and now embeds into HTML and structured text, not just photographs. It is a real control with three real limits.

Read article
Salzburg Salzach Old Town Dusk
AI NewsAI Architecture·

Fine-Tuning Writes Your Data Into the Model

Every organisation customising AI faces the same build decision: prompt it, retrieve for it, or fine-tune it. It is usually argued on accuracy and cost. The axis nobody raises is reversibility. Retrieval leaves your data in a store you own, audit and delete. Fine-tuning copies it into a model artefact you cannot meaningfully un-write, which makes the customisation call a records decision before it is an engineering one.

Read article
Bangkok Chao Phraya Dusk
AI NewsAnalysis·

Internal Audit's AI Say-Do Gap Now Has Numbers

Two 2026 surveys put hard numbers on something internal audit has felt for a year: adoption is racing ahead of capability. Gartner has 83 per cent of audit functions piloting or using AI, while only a small share feel able to embed it. The IIA and AuditBoard have 85 per cent alert to AI-enabled fraud and fewer than 40 per cent ready to detect it. For an Australian function, the gap is a benchmark to self-assess against, not a headline to read past.

Read article
Nice Promenade Des Anglais Dusk
AI NewsAI Governance·

Your AI Logs the Tokens. Not the Decision.

Your AI telemetry records what the call cost, not what the model was told or what it said. Every content attribute in the OpenTelemetry GenAI conventions ships opt-in, and the conventions warn the message content is likely to hold personal information. That is a privacy default, not an audit default, and the two pull in opposite directions. Here is the capture, redaction and retention decision nobody is being asked to make.

Read article
Seville Torre Del Oro Dusk
AI NewsCapability·

Structured Outputs: Make Your AI Return Data You Can Audit

Most teams still treat an AI answer as prose to read and re-key. Structured outputs change that. You define a schema, the model is forced to fill it, and you get validated, type-safe data your systems can check. That makes an AI pipeline auditable, but schema-valid is not the same as true, so the human verification step does not go away.

Read article
Manila Bay Skyline Dusk
AI NewsAI Strategy·

Google Missed Its Own Release Date, and That Is the Story

Google promised Gemini 3.5 Pro for June 2026. It is mid-July and the flagship still is not generally available, held back over quality Google will not sign off. In a market that worships launch velocity, a missed date is the underreported signal, and a live test of your own buying discipline.

Read article
Gdansk Motlawa River Blue Hour
AI NewsAI Security·

A Real CVE in Your Agent-Building Tools

A critical flaw in Langflow, tracked as CVE-2026-33017, let anyone run code on exposed servers with a single unauthenticated request, and attackers used it to install cryptominers within a day of disclosure. The vulnerability was not in a model. It was in the low-code tool teams use to build agents. Here is what that means for anyone evaluating an agent-building platform.

Read article
Budapest Danube Parliament Blue Hour
AI NewsCapability·

Your AI Agent Can Remember Now. Govern What It Keeps.

In 2026 the major labs shipped persistent memory as a first-class agent feature, barely six weeks apart. An agent that remembers across sessions is a different thing to govern, and a new attack surface. Treat the memory store as a governed data asset with write rules, provenance, expiry and rollback, not invisible plumbing.

Read article
Wollongong Crown Street Dusk
AI NewsWorkforce·

What 9,700 Real Users Actually Do With Claude

Most debate about AI and work runs on anecdote. Anthropic's June 2026 Economic Index, Cadences, offers something rarer: behavioural data on what roughly 9,700 real users do with AI, matched to how they feel about their careers. Almost every conversation produces real work, and the heaviest delegators are the most optimistic. Here is what a people leader should take from it.

Read article
Athens Acropolis View Blue Hour
AI NewsCapability·

Ground the Model, Do Not Trust Its Memory

A weak model with the right tool beat a strong model working from memory. Anthropic's biology-agent benchmark put numbers on it: accuracy ran as low as 16.9% from recall and cleared 99.7% once grounded in the authoritative source. The lesson holds for every regulated workflow that turns on a rule, rate or standard. Ground the model, do not trust its memory.

Read article
Melbourne Docklands Victoria Harbour Dusk
AI NewsAnalysis·

Canberra Just Measured What AI Is Doing to Jobs. It Found 2%.

The Australian Government has published its first systematic measurement of AI's effect on employment. DEWR's July 2026 report finds the most AI-exposed occupations grew 5.6 per cent since ChatGPT arrived, against 9.5 per cent for the least exposed, and models a 2 per cent shortfall against trend. The number is small, the caveats are real, and the implications for WHS, workers compensation, GRC, HR and leadership teams start now.

Read article
Bilbao Nervion Riverfront Blue Hour
AI NewsAI Governance·

Your AI Passed the Pilot. Production Is a Different Test.

A pilot that passed proves the AI worked once, on that data, on that version of the model. Then the model changes underneath you, the data shifts and usage drifts, and the thing you signed off quietly stops being the thing running. The answer is a standing evaluation harness, not a launch-day test. Here is how to build one, and why regulated work needs it most.

Read article
Ho Chi Minh City Saigon River Dusk
AI NewsAI Agents·

More Agents Is Not More Intelligence. Govern the Coordination.

The plumbing for multi-agent AI just got standardised, so building systems where agents talk to each other is now easy. That is exactly why the useful question changed. Not can you wire agents together, but should you, and how do you govern the coordination when more agents is not more intelligence.

Read article
Fukuoka Naka River Blue Hour
AI NewsWorkplace Privacy·

GPT-Live Makes Voice a Work Interface. Check What Gets Recorded

OpenAI's GPT-Live can listen and speak at the same time, making voice feel closer to a continuous work interface than a turn-by-turn chatbot. It is rolling out to consumer ChatGPT plans first, not Business, Enterprise or Edu. That gap makes recording, retention and disclosure rules the immediate workplace question.

Read article
Port Hedland Iron Ore Port Dusk
AI NewsAI Infrastructure·

AI's Next Constraint Is Power. Australia Has Started Writing the Rules

Australia is starting to treat AI infrastructure as an energy-system issue. Government expectations now ask new data centres to add clean supply, pay their grid costs and support flexible demand, while a draft AEMC rule would set technical connection standards for large loads.

Read article
Santiago Sky Costanera Dusk
AI NewsAI Strategy·

Model Routing Cuts AI Bills. It Also Moves Your Data.

The enterprise AI story has shifted from which model is best to which one you can afford to keep using, and buyers are moving from tokenmaxxing to model routing. The instinct is right. But for Australian regulated work a cheaper model is usually a different provider in a different place, so every routing rule is also a Privacy Act and APRA data-flow decision.

Read article
Kwinana Industrial Coast Dusk
AI NewsAI Security·

Someone Poisoned the Tool Description. The Agent Did the Rest.

Microsoft's incident-response team has documented the first real-world attack on the Model Context Protocol: poison a tool's description and you redirect the agent, without touching its code, its credentials or its prompt. The site's earlier MCP piece predicted this. Here is what "least agency, not just least privilege" means as an operational control, not a slogan.

Read article
The Hague Binnenhof Dusk
AI NewsPolicy·

A Government Now Vets Who Gets the Model. File It as a Vendor Risk.

For the second time in a month, a US government put a frontier model behind a gate. This time it was an access list: roughly 20 vetted organisations get GPT-5.6, chosen name by name. The capability story is covered. The one that lands on your desk is procurement: government-imposed access conditions are now a vendor-risk category your due diligence has to name.

Read article
Reykjavik Harbour Blue Hour
AI NewsCapability·

AI Guardrails: The Safety Layer No Vendor Can Ship for You

A new default model does not make your AI system safe. Reliability and safety in production come from the guardrail layer you build around the model: input rails, grounding, output rails and action gates. Here is the architecture, a worked example that turns a written policy into running rails, and the prompts and checklist to build your first rail this week.

Read article
Barcelona Port Vell Blue Hour
AI NewsAI Agents·

You Are Now Buying Software for Agents, Not People

Gartner says $234 billion of enterprise SaaS spend is exposed to agentic arbitrage by 2030. Read as a vendor problem it is a headline. Read as a buyer it changes how you procure and govern the software you already run, so this piece turns the forecast into an API-parity test you can run this week, a five-clause contract checklist and a Monday workflow.

Read article
Los Angeles Downtown Dusk
AI NewsModel Release·

Claude Sonnet 5 Became the Default. That Is a Change Event.

Anthropic released Claude Sonnet 5 on 30 June and made it the default in Claude Code and on Claude.ai Free and Pro. Almost nobody chooses a model, so a frontier swap is a silent change to a system you may have already validated. Here is how to treat it as a change event: the prompts, the Monday workflow and the register entry.

Read article
Washington Dc Potomac Blue Hour
AI NewsPolicy·

Fable 5 Returns With a Jailbreak Severity Framework

Claude Fable 5 comes back globally on 1 July, three weeks after a US directive pulled it. The return matters less than what came with it: a safety patch that over-blocks routine coding, and a four-dimension jailbreak-severity framework the major labs are building together.

Read article
Bengaluru Ub City Dusk
AI NewsAnalysis·

AI Cyber Defence Just Scaled Up. Mind Your Open-Source Dependencies.

OpenAI pointed its most capable cyber model at the open-source software the world runs on, and found hundreds of real flaws in days. The capability is dual-use. Here is what it means for Australian teams.

Read article
Guangzhou Pearl River Blue Hour
AI NewsAnalysis·

AI Agents Just Went From Minutes to Hours. The Control Point Is Where They Run.

OpenAI bought Ona and published research showing AI agents now run for hours, not seconds. The unit you have to govern moved from the prompt to the environment the agent runs in.

Read article
Tel Aviv Skyline Blue Hour
AI NewsModel Release·

GPT-5.6 Sol Lands. The Frontier Just Got Gated.

On 26 June OpenAI previewed GPT-5.6, a new three-model family it calls its strongest yet. The capability is real, but the news is the access: at the US government's request it launched to a handful of vetted partners, not to you. For the second time in a month a US lab's best model is gated by government. Frontier access is now a policy variable, and your AI plan needs to assume it.

Read article
Milan Porta Nuova Blue Hour
AI NewsCapability·

Context Engineering: What the Model Is Allowed to See

The reliability of an AI system is decided less by how you word the prompt and more by what you let into the context window. Context engineering is the named discipline for that, and it is the highest-leverage AI skill for anyone doing real work, especially in regulated settings.

Read article
Phoenix Downtown Dusk
AI NewsAI Infrastructure·

OpenAI Built Its Own Chip. The Real Story Is the Cost of Intelligence.

On 24 June, OpenAI and Broadcom unveiled Jalapeño, OpenAI's first custom chip, built to run its models more cheaply. The coverage is about a strike at Nvidia. The useful signal for a practitioner is the opposite of hardware: it is the falling cost of intelligence, and what that does to your AI decisions and your governance. Cost has quietly been holding AI back. That fence is coming down.

Read article
Hamburg Hafencity Blue Hour
AI NewsAI Agents·

Your AI Assistant Just Became a Shared Teammate. Govern the Channel.

On 23 June, Anthropic launched Claude Tag, a single shared Claude that lives in a Slack workspace with its own memory and admin-scoped access to channels, tools and data. The unit of AI collaboration just moved from the private conversation to the team channel. The thing you now have to govern is no longer a prompt. It is a standing presence. Here is what changes, and the three decisions to make before it is live.

Read article
Munich Financial Blue Hour
AI NewsAI Strategy·

Model Context Protocol: The Standard Wiring AI Into Your Tools

In eighteen months the Model Context Protocol went from an Anthropic experiment to the way AI plugs into your tools and data. Understanding what it is matters less than governing the connectors, because each one is a new door into your systems. Here is the capability and the control work.

Read article
Taipei Skyline Blue Hour
AI NewsModel Release·

The Strongest Open Model Is Now Chinese. Mind Where Your Data Goes.

On 16 June, China's Z.ai released GLM-5.2 under an MIT licence with no regional limits, the highest-ranked open-weights model on its own coding benchmarks. With Anthropic's Fable 5 pulled by a US directive, the strongest model you can simply download and run is now Chinese. The decision that carries your risk is not the model. It is whether you run the open weights yourself or send your data to the hosted API.

Read article
Dublin Docklands Blue Hour
AI NewsCapability·

ChatGPT Just Got Better at Health. Mind the Boundary.

On 18 June OpenAI announced a substantial step up in ChatGPT's health intelligence, free to the 230 million people who already ask it health questions every week. Better answers do not move the boundary between information and a clinical decision. Here is what that means for Australian professionals this week.

Read article
Helsinki South Harbour Blue Hour
AI NewsAI Strategy·

Stop Trusting the Leaderboard: Evaluate AI on Your Own Work

A new frontier model lands most months, the public benchmarks they tout are methodologically shaky, and the demo always wins. The only evidence that should move your money is performance on your own work. Here is how to test it, using a private evaluation Project you build yourself.

Read article
Austin Lady Bird Lake Dusk
AI NewsAI Agents·

Business Teams Can Now Build Their Own AI Agents

Databricks launched Genie One this week, an agentic coworker pitched at finance and marketing teams, not engineers. The real shift is who holds the build button, and where that moves the control point. Here is what to do this week, with a governance prompt you can run today.

Read article
Gold Coast Surfers Paradise Twilight
AI NewsAI Security·

The OWASP Agentic Top 10: A Defence Playbook for the Agents You Are Deploying

OWASP has published a Top 10 built specifically for AI agents. It reframes the agent as a privileged user that reads untrusted text and acts with your access. Here is the practical defence playbook.

Read article
Osaka Umeda Skyline Dusk
AI NewsAI Strategy·

AI Is Moving Into the Core Systems of Regulated Work

This week two of the world's largest IT services firms began wiring a frontier model into the core systems that banks, insurers and airlines run on, not the chat window. Here is what it means for regulated work, and what to do this week.

Read article
Stockholm Gamla Stan From Water Dusk
AI NewsAnalysis·

AI Week in Review, 8-14 June 2026: A Frontier Model Pulled by Government Order

The week a US directive forced Anthropic to suspend two new frontier models worldwide, plus six verified vendor moves and a repeatable method for turning AI news into Monday actions.

Read article
San Francisco Bay Skyline Dusk
AI NewsAnalysis·

Claude Fable 5: Frontier Capability, With Conditions Attached

Anthropic has put a Mythos-class model on general release, and the conditions matter as much as the capability. A silent classifier fallback, a mandatory 30-day retention policy and a 23 June billing switch all belong in your next third-party AI assessment.

Read article
Seattle Waterfront Space Needle Blue Hour
AI NewsAnalysis·

Gemini 3.5 Flash: Google Makes the Agent the Default

Google made an agentic model the worldwide default in the Gemini app and AI Mode in Search before the flagship even shipped. The benchmark and pricing evidence says Flash genuinely replaces last generation's Pro, and millions of workers got a more autonomous default model overnight.

Read article
Boston Back Bay Charles River Dusk
AI NewsAnalysis·

Microsoft's Seven MAI Models: The In-House Bet Under Copilot

Microsoft launched seven home-grown MAI models at Build 2026 and started swapping them into Copilot and the Microsoft 365 stack. For practitioners the story is procurement, not benchmarks: data lineage claims, weight tuning, and a billing change in the same week.

Read article
Sydney Harbour Night
AI NewsAI Agents·

AI Agents Need Approval Gates Before They Need Autonomy

Autonomous AI agents are becoming practical, but organisations should design approval gates, permissions and evidence trails before granting action rights.

Read article
Canberra City Dusk
AI NewsWorkforce·

AI Upskilling Will Fail If HR Does Not Redesign the Work

Training people to use AI is useful, but HR also needs to redesign roles, capability frameworks and quality controls around changed work.

Read article
Brisbane River Dusk
AI NewsAI Trends·

Small Models, Edge AI and the Next Governance Blind Spot

As AI moves into devices, business apps and smaller specialised models, organisations need governance that looks beyond frontier models and public chatbots.

Read article
Perth Skyline Dusk
AI NewsWorkplace Privacy·

Workplace AI and Privacy: The Trust Test HR Cannot Outsource

AI productivity tools can reshape workplace data collection, monitoring and employee trust. HR needs a privacy-first governance model before adoption scales.

Read article
Melbourne Flinders Dusk
AI NewsAI Strategy·

The AI Pilot-to-Scale Gap Is an Operating Model Problem

Most organisations can run AI pilots. Far fewer can scale them safely, consistently and usefully across real work.

Read article
Adelaide City Dusk
AI NewsAI in Hiring·

AI in Hiring Needs Human Review Before It Needs Another Tool

Australian HR teams can use AI in recruitment, but hiring workflows need privacy discipline, bias checks, candidate transparency and accountable human judgement.

Read article
Shanghai
AI NewsAnalysis·

Agentic Browsing: What Actually Shipped This Month

Three agentic browsing platforms shipped meaningful updates in April. The demos are convincing. The production reliability is not. Where these agents work, where they fail, and what to do this quarter.

Read article
Toronto
AI NewsQuick Brief·

On-Device AI at Work: Apple Intelligence and Pixel Gemini Nano

On-device AI is enterprise-ready in narrow ways and not in the ways the demos suggest. Apple Intelligence and Pixel Gemini Nano in April 2026: what works, what does not, and the real privacy story.

Read article
Yokohama
AI NewsQuick Brief·

2M-Token Multimodal Contexts: Where They Actually Pay Off

Two-million-token multimodal context is real. The marketing says it replaces RAG. The production data says it does not. Three workflows where it pays off and three where it does not.

Read article
Tokyo Shibuya Rain
AI NewsAnalysis·

The Open-Source Frontier in April 2026: Llama 4, DeepSeek R2, Mistral Sovereign

Three serious open-weight contenders shipped in April 2026. None of them is the right answer for every workload, but each has carved out a defensible enterprise niche. Here is the comparison.

Read article

News Posts

Rapid updates when AI news breaks

View all posts →

Concise rapid updates when AI news breaks. 150-200 words, no filler, straight to the signal. Available on the site and cross-posted to X (@TheAICommand) and Instagram (@the_aicommand).

News

Build 2026 makes agents first-class citizens of the Microsoft stack

Microsoft used [Build 2026](https://blogs.microsoft.com/blog/2026/06/02/microsoft-build-2026-be-yourself-at-work/) to make agents first-class citizens of its stack, and the governance tooling arrived alongside the capability for once. Microsoft IQ, a context layer spanning Work IQ, Fabric IQ, Foundry IQ and Web IQ, is generally available across GitHub Copilot, Foundry and Copilot Studio, grounding agents in Microsoft 365 data through APIs that go live on 16 June. Microsoft Execution Containers enter preview as OS-enforced sandboxes that contain what an agent can touch, and ASSERT plus the Agent Control Specification are open-sourced for standardised agent safety evaluation. The headline for compliance teams is Agent 365: Entra, Defender and Purview extended into a unified control plane where agents get identities, security posture and compliance treatment the way employees do. The framing to take into your next architecture discussion: Microsoft is now assuming organisations will [run fleets of agents](/ai-news/more-agents-is-not-more-intelligence), and is selling the management layer. If your AI governance still models one user prompting one chatbot, the vendor roadmap has already moved past your risk register.

News

OAIC survey finds trust in AI companies has collapsed to 4 per cent

The Office of the Australian Information Commissioner has released its triennial [Australian Community Attitudes to Privacy Survey](https://www.oaic.gov.au/news/media-centre/australians-more-concerned-about-privacy-as-trust-in-ai-languishes,-survey-finds), and the AI numbers are stark. Just 4 per cent of Australians trust AI companies. Only social media platforms rank lower, at 3 per cent. The broader trend is sharpening: 87 per cent of respondents are more concerned about privacy than five years ago, and privacy complaints to the OAIC are up 73 per cent this financial year to date. The survey was run by the Social Research Centre in March 2026 with 1,511 nationally representative adults. Privacy Commissioner Carly Kind noted that "wariness of emerging technologies is increasing, particularly in terms of fairness, accountability and the practical ability to exercise rights." The number worth building strategy on: 68 per cent would be more likely to use digital services if they knew data was handled fairly and responsibly. For any team [deploying AI on customer or employee data](/ai-news/workplace-ai-and-the-privacy-trust-test), the complaint pathway is not a side process. It is part of the control environment, and now a measurable trust asset.

News

Mistral puts frontier-class weights on four GPUs with Medium 3.5

Mistral has released [Medium 3.5](https://mistral.ai/news/vibe-remote-agents-mistral-medium-3-5/), a 128 billion parameter dense model with a 256k context window that folds instruction-following, reasoning and coding into a single set of weights. It posts 77.6 per cent on SWE-Bench Verified and 91.4 on the agentic telecom benchmark. Two release details matter more than the benchmarks. The weights are open, [published on Hugging Face](https://huggingface.co/mistralai/Mistral-Medium-3.5-128B) under a modified MIT licence that permits commercial use with carve-outs for high-revenue companies. And the model self-hosts on as few as four GPUs, with API pricing at $1.50 per million input tokens and $7.50 output for those who would rather not. The release also ships Vibe remote agents, asynchronous sandboxed cloud coding sessions that integrate with GitHub, Jira and Slack. For regulated Australian entities weighing [data residency](/ai-news/glm-5-2-open-weights-and-data-sovereignty), APRA-style vendor concentration questions and exit strategies, a frontier-class model that runs inside your own perimeter is no longer hypothetical. The procurement conversation has a new comparison point.

News

ASIC research maps AI spreading through underwriting and claims

ASIC has released new research on financial system innovation, and the AI finding deserves more attention than the headline. The [Innovation in Financial Technology and RegTech report](https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-102mr-australia-well-placed-to-unlock-opportunities-from-innovation-in-the-financial-system/), conducted by the Digital Finance Cooperative Research Centre, finds AI becoming embedded in credit underwriting, claims processing, portfolio management and disclosure. That list is the point. These are core decisioning functions, not edge pilots, and each carries consumer outcomes a regulator can test. Chair Joe Longo framed [the posture](/grc/asic-april-2026-ai-statement-decoded): "ASIC's role is to make sure that when innovation happens, it happens safely and responsibly, with the wellbeing of end consumers at the forefront." The release leans optimistic, noting Australian startups raised over $5 billion in venture capital in 2025, the third-best year on record, with strength in payments infrastructure. Next steps are principles-based regulation through regulatory simplification and industry engagement via the Digital Finance Advisory Panel and targeted roundtables. For risk teams, the message is simple: if AI sits in your underwriting or claims chain, assume ASIC now knows it does.

News

Google I/O 2026: agents get desktops, sandboxes and enterprise plumbing

Google's [I/O 2026 announcements](https://blog.google/innovation-and-ai/technology/ai/google-io-2026-all-our-announcements/) had one organising idea: the agent is the product now. Antigravity 2.0 arrives as a desktop app that runs multiple agents on parallel tasks, with a CLI and SDK, and connects to Google Cloud projects under enterprise terms. The infrastructure followed. Managed Agents in the Gemini API provision remote Linux environments where agents reason, plan and execute tools without a developer babysitting the runtime. Gemini Omni, a multimodal creation model, generates video from image, audio, text and video inputs, with SynthID watermarking attached, a provenance detail governance teams should note. Workspace gets the everyday layer: AI Inbox drafting replies, plus Docs Live and Gmail Live voice features rolling out from mid-2026. Gemini 3.5 Pro was flagged as coming next month. For Australian workplaces the practical question shifts from which chatbot to license towards [who supervises parallel agents](/ai-news/ai-agents-need-approval-gates) doing real work, on which data, with what logging. The tooling is arriving faster than most operating rhythms.

News

ASIC demands urgent cyber uplift as frontier AI raises the threat level

ASIC Commissioner Simone Constant has issued an [open letter to AFS licensees, market participants and their directors](https://www.asic.gov.au/about-asic/news-centre/find-a-media-release/2026-releases/26-092mr-asic-calls-for-urgent-cyber-uplift-as-ai-accelerates-cyber-threats/) calling for an urgent cyber uplift. The trigger is frontier AI: "Cyber risk has entered a new era. The advent of frontier AI models creates opportunity, but also materially increases risk." The language is unusually direct for a regulator: "The clock is at a minute to midnight. If you aren't on top of your cyber resilience already, the time to act and prepare is right now." The letter sets out a 12-point action list covering cyber plan reassessment, critical asset protection, patching, access privileges, third-party risk and using AI defensively, plus four [board governance](/grc/ai-cyber-risk-board-governance) expectations. It is principles-based and model-agnostic, and it frames cyber resilience as a core licensing obligation rather than an IT issue. The operational detail to act on first: ASIC instructs that the letter itself be tabled and discussed at the ultimate board and risk governance committees. If it is not on your next agenda, that is the gap.